Critical Atlassian Flaw Exploited to Deploy Linux Variant of Cerber Ransomware
ID: d9395ef0-22e9-5dcd-bb74-0c3d32eb0d2a
STIX ID: report--d9395ef0-22e9-5dcd-bb74-0c3d32eb0d2a
Feed Name: The Hacker News
Threat actors are exploiting the critical Atlassian Confluence vulnerability CVE-2023-22518 to create administrator accounts and deploy an Effluence web shell that downloads and runs a Linux variant of the Cerber (C3RB3R) ransomware. The C++ loader retrieves additional payloads from a C2 server, launches an encryptor that appends a .L0CK3D extension and drops ransom notes, but observed attacks encrypt primarily files owned by the low-privilege 'confluence' user and show no evidence of data exfiltration; the report also situates this campaign amid numerous new and forked ransomware families leveraging leaked code and builder tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
